Files
poky/meta/recipes-multimedia
Sudhir Dumbhare d0d68df4c3 libpng: Fix CVE-2026-34757
These patches apply the upstream fixes [1][2], which address
getter-to-setter aliasing issues in libpng chunk setters that could
cause stale-pointer reads, as described in [3].

[1] 398cbe3df0
[2] 55d20aaa32
[3] https://github.com/pnggroup/libpng/issues/836

Reference:
https://security-tracker.debian.org/tracker/CVE-2026-34757
https://nvd.nist.gov/vuln/detail/CVE-2026-34757

Test results on qemux86-64 using ptest-runner:
START: ptest-runner
2026-06-04T11:29
BEGIN: /usr/lib/libpng/ptest
PASS: tests/pnggetset
Testsuite summary
# TOTAL: 33
# PASS:  33
# SKIP:  0
# XFAIL: 0
# FAIL:  0
# XPASS: 0
# ERROR: 0
DURATION: 80
END: /usr/lib/libpng/ptest
2026-06-04T11:31
STOP: ptest-runner
TOTAL: 1 FAIL: 0

(From OE-Core rev: 392fb4216357fd4eefb6abe3788414f2e60b0889)

Signed-off-by: Sudhir Dumbhare <sudumbha@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
2026-07-30 13:21:16 +01:00
..
2026-02-27 17:45:07 +00:00
2024-07-12 05:47:20 -07:00
2024-10-30 08:30:00 -07:00
2021-06-12 22:54:14 +01:00
2026-07-30 13:21:16 +01:00
2026-06-26 16:55:53 +01:00
2025-03-19 07:25:56 -07:00
2022-06-22 22:40:28 +01:00
2024-01-07 12:24:57 +00:00
2023-09-20 08:57:27 +01:00